audit.c 1.7 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384
  1. #include <linux/init.h>
  2. #include <linux/types.h>
  3. #include <linux/audit.h>
  4. #include <asm/unistd.h>
  5. static unsigned dir_class[] = {
  6. #include <asm-generic/audit_dir_write.h>
  7. ~0U
  8. };
  9. static unsigned read_class[] = {
  10. #include <asm-generic/audit_read.h>
  11. ~0U
  12. };
  13. static unsigned write_class[] = {
  14. #include <asm-generic/audit_write.h>
  15. ~0U
  16. };
  17. static unsigned chattr_class[] = {
  18. #include <asm-generic/audit_change_attr.h>
  19. ~0U
  20. };
  21. static unsigned signal_class[] = {
  22. #include <asm-generic/audit_signal.h>
  23. ~0U
  24. };
  25. int audit_classify_arch(int arch)
  26. {
  27. if (audit_is_compat(arch))
  28. return 1;
  29. else
  30. return 0;
  31. }
  32. int audit_classify_syscall(int abi, unsigned syscall)
  33. {
  34. if (audit_is_compat(abi))
  35. return audit_classify_compat_syscall(abi, syscall);
  36. switch(syscall) {
  37. #ifdef __NR_open
  38. case __NR_open:
  39. return 2;
  40. #endif
  41. #ifdef __NR_openat
  42. case __NR_openat:
  43. return 3;
  44. #endif
  45. #ifdef __NR_socketcall
  46. case __NR_socketcall:
  47. return 4;
  48. #endif
  49. #ifdef __NR_execveat
  50. case __NR_execveat:
  51. #endif
  52. case __NR_execve:
  53. return 5;
  54. default:
  55. return 0;
  56. }
  57. }
  58. static int __init audit_classes_init(void)
  59. {
  60. #ifdef CONFIG_AUDIT_COMPAT_GENERIC
  61. audit_register_class(AUDIT_CLASS_WRITE_32, compat_write_class);
  62. audit_register_class(AUDIT_CLASS_READ_32, compat_read_class);
  63. audit_register_class(AUDIT_CLASS_DIR_WRITE_32, compat_dir_class);
  64. audit_register_class(AUDIT_CLASS_CHATTR_32, compat_chattr_class);
  65. audit_register_class(AUDIT_CLASS_SIGNAL_32, compat_signal_class);
  66. #endif
  67. audit_register_class(AUDIT_CLASS_WRITE, write_class);
  68. audit_register_class(AUDIT_CLASS_READ, read_class);
  69. audit_register_class(AUDIT_CLASS_DIR_WRITE, dir_class);
  70. audit_register_class(AUDIT_CLASS_CHATTR, chattr_class);
  71. audit_register_class(AUDIT_CLASS_SIGNAL, signal_class);
  72. return 0;
  73. }
  74. __initcall(audit_classes_init);